Multi-module collaborative domain penetration automatic vulnerability utilization method and system

Through the multi-module collaborative domain penetration automatic vulnerability utilization method and system, the problems of the existing penetration testing methods are solved in complex network environments, and efficient and automated penetration testing is achieved, which improves testing efficiency and effectiveness.

CN120017415AActive Publication Date: 2025-05-16NANJING NANZI DIGITAL SECURITY TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510465670.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-16
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

The existing penetration testing methods have low adaptability and execution efficiency in complex network environments, making it difficult to meet the needs of modern network security protection systems for efficient and precise penetration testing.

Method used

The automatic vulnerability utilization method and system of domain penetration is adopted with multi-module collaboration, and the vulnerability is exploited through multi-module collaboration, and combined with the dynamic module orchestration mechanism, automated information collection and automated penetration testing are completed.

Benefits of technology

It realizes efficient and automated penetration testing in complex network environments, greatly saving manpower and time costs, able to fully cover all the processes of domain penetration, and improves testing efficiency and effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017415A_ABST
    Figure CN120017415A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-module collaborative domain penetration automatic vulnerability utilization method and system, and the system integrates a routing agent module, an information collection module, an authority promotion module, a transverse movement module, a cross-domain attack module and a session management module, introduces an intelligent arrangement engine, breaks through the problems of fixed process and single path of a traditional penetration test, and improves the reliability of the test. And the dynamic adjustment and optimization of the permeation process are realized. Through multi-module cooperation and a dynamic arrangement mechanism, automatic vulnerability utilization can be performed according to real-time changes of a target domain environment. According to the method, the network information of the domain environment can be completely collected, the method adapts to the multi-domain, multi-service, multi-host and multi-user complex environment to obtain the high authority of the sub-domain or the root domain, and manpower, material resources and time cost are greatly saved. And meanwhile, the use threshold and learning cost of penetration personnel are further reduced, and a convenient, intelligent and controllable safety protection test scheme is provided for safety protection tests of enterprises, schools and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cyberspace security technology, and in particular relates to a multi-module collaborative domain penetration automatic vulnerability exploitation method and system. Background Art

[0002] With the rapid development of information technology, the network has become an important part of social infrastructure and is widely used in various organizations such as enterprises, government agencies, scientific research institutions and universities. However, with the continuous expansion of network scale and the increasing complexity of information systems, network security issues have become more and more serious. Attackers often use system vulnerabilities and network configuration defects to carry out attacks. In order to improve network defense capabilities, various organizations generally use penetration testing as a key means to evaluate and strengthen their own security. Penetration testing simulates the behavior of real attackers and actively detects the security weaknesses of the target network so as to repair security risks before hackers exploit vulnerabilities and enhance overall defense capabilities. In the penetration test process, domain penetration is a key link. Its core goal is to further penetrate the internal network after breaking through the outer defense line, and use the controlled WEB server, database or other key nodes as a springboard to gradually expand the control scope of the entire intranet. In the end, the attacker may obtain sensitive database information, control a large number of high-value servers, and even capture the domain controller (DC) in the domain environment, thereby completely controlling the entire domain network. The complexity and concealment of domain penetration make it the focus and difficulty of network security protection. Traditional security reinforcement strategies often find it difficult to detect such potential threats in a timely and comprehensive manner.

[0003] The current penetration test work still mainly relies on manual operation by penetration test experts. Testers need to collect information, analyze vulnerabilities, exploit attacks, maintain permissions, and obtain data on the target system based on their own experience and skills. The whole process requires high professional ability, and at the same time puts forward high requirements on the tester's knowledge reserve, practical experience, and analytical judgment ability. In actual testing, penetration personnel may need to face complex large-scale enterprise intranets involving dozens or even hundreds of hosts, and the differences in different systems, applications, and network architectures further increase the difficulty of penetration work. Due to the low efficiency of manual penetration testing, testers often find it difficult to cover the entire target network in a timely and comprehensive manner, which may result in some security vulnerabilities not being effectively discovered and exploited, reducing the effectiveness of penetration testing. In addition, during the penetration test process, multiple tools need to be used to coordinate tasks at different stages, such as information collection tools (such as Nmap, Masscan), vulnerability exploitation tools (such as Metasploit, Cobalt Strike), and permission maintenance tools (such as Empire, Mimikatz). These tools often require testers to manually configure and operate, which not only increases time costs, but also causes additional consumption of system resources, and the overall test efficiency is seriously restricted.

[0004] In recent years, with the development of automation technology, some penetration testing tools have begun to try to automate some processes to reduce reliance on manual decision-making. However, these tools can often only provide semi-automatic assistance in specific links, and it is difficult to cover the entire penetration testing process. For example, some vulnerability scanning tools can automatically discover known vulnerabilities, but still require penetration testers to manually analyze and exploit them; some attack frameworks can automatically execute part of the attack chain, but lack intelligent decision-making capabilities and cannot dynamically adjust attack strategies according to the test environment. Therefore, the adaptability and execution efficiency of existing penetration testing methods in complex network environments still have significant limitations, and cannot meet the needs of modern network security protection systems for efficient and accurate penetration testing. Summary of the invention

[0005] In order to solve the above technical problems, the present invention provides a multi-module collaborative domain penetration automatic vulnerability exploitation method and system, which aims to complete automated information collection and automated penetration testing by exploiting vulnerabilities through multi-module collaboration and combining the module dynamic orchestration mechanism.

[0006] The technical solution provided by the present invention is specifically as follows: A multi-module collaborative domain penetration automatic vulnerability exploitation method, comprising the steps of: S1. Establish an initial session from the boundary host of the target network, perform cross-segment detection and set up a routing proxy; S2, identify live hosts and open ports in the target network, and collect host information and domain information; S3, elevating the privilege level of the current session through operating system vulnerabilities or configuration flaws; S4. Use the obtained permissions to move laterally and expand the scope of penetration attacks; S5. Carry out cross-domain penetration attack after successful lateral movement.

[0007] Further, step S1 includes: Obtain and analyze network card information in the initial session to determine whether the host has multiple network segments; if there are multiple network segments, it is necessary to establish routes and set up intranet proxies; monitor proxy stability in real time, and automatically rebuild or switch routes if the proxy is interrupted: assign a dynamic routing weight score to each network segment. If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the backup path switching process and use the backup path with the highest dynamic routing weight score.

[0008] Furthermore, the dynamic routing weight score is expressed as: , in, Indicates i The comprehensive routing weight score of each network segment, Indicates i The available bandwidth ratio of each network segment, and , For the i The current network load of each network segment, The maximum bandwidth of the network card; Indicates i The bandwidth utilization of each network segment, and ; Indicates i The stability coefficient of each network segment, that is, the proxy success rate within the set time; For the i The average response delay ratio of the network segments, w 1~ w 4 is the coefficient of each factor.

[0009] Further, step S2 includes: Deploy a host information collection script on the host where the current session is located to collect host information, including the host name, domain name where the host is located, system architecture, operating system version, and current logged-in user; Deploy a domain information collection script on the host where the current session is located to collect basic domain information and other domain information. The basic domain information includes the forest root domain name, all domain controller names, all child domain names, the parent domain name, the current domain name and the primary domain controller name. The other domain information includes domain services, logged-in domain users, domain high-authority group members, and domain delegation information.

[0010] Furthermore, after collecting the host information, dynamically adjust the parameters of the information collection script and filter the key data in real time: First, the host is classified and judged based on the collected information to form a policy label: if the host runs a server version operating system, it is marked as a "key node"; if it is a client operating system, it is marked as a "normal domain member"; if the system role includes "domain controller", "DNS server" and "file sharing", it is marked as a "high-value target"; if it is not joined to the domain or has no domain information, it is marked as a "non-domain member" or "peripheral host"; Then, according to the classification results, the parameters of the information collection script are dynamically adjusted: for "ordinary domain member" hosts, basic user information enumeration is performed to obtain logged-in users, domain user group members, service information, and scan local open ports and simple LDAP information; for "high-value target" hosts, LDAP deep query is added to obtain all domain users, domain control lists, domain trust relationships, try to read key account permissions, enable ACL enumeration and SID history field recognition, and check whether DCSync attacks or forged tickets are allowed; for "key node" hosts, credential, token, and key extraction behaviors are strengthened.

[0011] Further, step S4 includes: S401, check whether there are high-authority credentials or processes in the domain on the local machine, and if so, directly steal the token; S402, traverse the host that has not been attacked, obtain the host information and call the corresponding common vulnerability to attack; S403, traverse the unattacked domain services, obtain the service information and call the corresponding service vulnerability to attack; S404, using domain-related vulnerabilities to attack the domain environment itself and obtain the credentials of the domain controller's krbtgt user; If the token theft in S401 is successful, the vulnerability attack process will be immediately suspended, and lateral movement using credentials will be prioritized; if the vulnerability attacks in S402~404 fail continuously, it will automatically switch to the password blasting or phishing module.

[0012] Furthermore, step S5 includes: traversing all acquired sessions and credentials, selecting high-authority sessions and credentials, using the acquired high-authority credentials to directly attack the root domain through SID-History to obtain the root domain high-authority credentials; if the SID-History attack fails, Golden Ticket forgery or DNS hijacking is performed.

[0013] Furthermore, the security protection level of the root domain is evaluated to obtain the defense strength level, and corresponding cross-domain penetration attack strategies are adopted according to the defense strength level of the root domain: for low defense strength, the attack is executed immediately without hiding, and SID-History is used directly; for medium defense strength, the attack strategies include adding attack delays, simulating normal traffic disguise before execution, and delaying the delivery of attack payloads; for high defense strength, the attack strategies include reducing the attack frequency, disguising user behavior, Golden Ticket forgery, and DNS hijacking.

[0014] A domain penetration automatic vulnerability exploitation system based on the above method, including a routing proxy module, an information collection module, a permission escalation module, a lateral movement module, a cross-domain attack module and an intelligent orchestration engine; The routing proxy module is used to set routes for cross-segment attack sessions and add intranet proxies. During session communication, the intelligent orchestration engine dynamically allocates routing weights based on the multi-NIC information of the border host and monitors the proxy stability in real time. If the proxy is interrupted, it automatically rebuilds or switches to an alternate route. The information collection module is used to collect information about the host where the session is located and obtain relevant information about the target domain. The privilege escalation module is used to elevate the privilege level of the session through operating system vulnerabilities or configuration defects. If the privilege escalation fails, the intelligent orchestration engine records the reason for the privilege escalation failure, dynamically blocks high-risk operations, and marks the current host as a "low-privilege temporary storage target"; The lateral movement module is used to utilize known vulnerabilities or credentials to move laterally in the target network and obtain high-privilege user credentials in the domain to expand the scope of penetration attack; The cross-domain attack module is used to launch a cross-domain penetration attack. During the cross-domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the cross-domain attack defense strategy. If the target root domain defense is strong, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering an alarm and being detected by the defense system.

[0015] Furthermore, it also includes a session management module for tracking and managing all penetration test sessions, recording session information and credentials obtained after a successful cross-domain attack, continuously monitoring the status of the controlled host, and timely updating the session management strategy after a cross-domain attack to ensure the validity of high-privilege sessions and credentials throughout the entire penetration process.

[0016] Compared with the prior art, the present invention has at least the following beneficial effects: Through the collaborative exploitation of vulnerabilities by multiple modules and combined with the dynamic arrangement mechanism of modules, the present invention can flexibly adjust the execution order and strategy of each module according to the real-time situation during the penetration process, complete the work of automated information collection and automated penetration testing, and greatly save manpower and time costs. For the automated penetration test in the domain environment, the present invention uses dynamic arrangement to achieve adaptation and optimization of complex environments, completely covering the entire process of domain penetration, and the completeness is far greater than the current semi-automatic penetration script, filling the gap of the current lack of automated penetration tools for domain penetration.

[0017] The present invention is easy to deploy and simple to operate. The dynamic module arrangement mechanism enables the system to adapt to a variety of network structures and defense strategies without human intervention. It only requires an online session and an attack host, which greatly reduces the usage threshold and learning cost of penetration testers. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. They are used to explain the present invention together with the embodiments of the present invention and do not constitute a limitation of the present invention.

[0019] Figure 1 It is a schematic diagram of a flow chart of information collection provided by an embodiment of the present invention; Figure 2 is a schematic diagram of a process of lateral movement provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of the framework of a domain penetration automatic vulnerability exploitation system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0020] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, other embodiments obtained by ordinary technicians in this field without making creative work are all within the scope of protection of the present invention.

[0021] Embodiment 1 This embodiment provides a multi-module collaborative domain penetration automatic vulnerability exploitation method, which penetrates the domain environment of the intranet from the perspective of a penetration tester. The method mainly includes the following steps: Step 1: Establish initial session and set up routing proxy When conducting a penetration test, you first need to establish an initial session from the boundary host of the target network. At this point, you need to detect the network environment and topology of the target host, perform cross-segment detection, and set up appropriate routes as needed to ensure the smooth progress of subsequent penetration operations.

[0022] The specific steps may include: S101. Collect network card information on the initial session of the border host, including IP address, subnet mask, network segment, etc., and obtain and analyze whether the host has multiple network segments.

[0023] S102. If the network where the host is located involves multiple subnets, for example, the IP of the target host is 192.168.1.100, the subnet mask is 255.255.255.0, and the host is also connected to another network segment 192.168.2.0 / 24, then routing settings and proxy establishment are required to ensure that communication with the target system can be achieved across different network areas.

[0024] S103. By setting up a proxy server (such as Socket5 proxy), the penetration traffic can communicate between the external network and the internal network through the proxy, ensuring that the penetration operation can be seamlessly connected between different network segments.

[0025] During the penetration process, the network is usually composed of multiple subnets, VLANs or physically isolated segments. Penetration testers often need to traverse between these different network segments to complete the penetration control of deep resources in the intranet. At this time, the ability to automatically adjust the routing strategy is of great significance to the efficiency, concealment and stability of the penetration test.

[0026] In this embodiment, routing weights are dynamically allocated according to the multi-network card information of the border host (such as giving priority to network segments with smaller proxy traffic), and proxy stability is monitored in real time. If the proxy is interrupted, the backup route is automatically rebuilt or switched.

[0027] Specifically, considering factors such as network load, bandwidth utilization, topological distance, path history stability, etc., a dynamic routing priority weight value is assigned to each network interface. i The comprehensive routing weight score of the network segment is W i ,but , in, Indicates i The available bandwidth ratio of each network segment, and , is the current network load, The maximum bandwidth of the network card; Indicates i The bandwidth utilization of each network segment, and , It is logically complementary, the lower the better, indicating that the current network segment is idle; is the average response delay ratio (current path RTT / maximum tolerated RTT), represents the path stability coefficient (the success rate of the agent in the past period of time), w 1~ w 4 is the coefficient of each factor, and the default value is 0.25. It can be set according to the task scenario. The higher the comprehensive route weight score, the better the path is, and it is preferred as the main route.

[0028] If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the backup path switching process and use the backup path with the highest comprehensive routing weight score. If the scores are close, the one with a higher stability coefficient will be selected first.

[0029] Step 2: Network scanning and information collection After successfully establishing a session and configuring the route, the next step of the penetration test is to collect information. The goal of this stage is to obtain as much target network and host information as possible to provide data support for subsequent vulnerability exploitation, privilege escalation, and attack path planning.

[0030] like Figure 1 As shown, this stage may specifically include the following steps: S201. Network scanning: Use tools such as Nmap and Masscan to perform port scanning to identify live hosts and open ports in the target network. Usually start scanning from the border hosts and gradually expand to the intranet.

[0031] S202. Host information collection: deploy a host information collection script on the host where the current session is located, such as using a PowerShell script (PowerView), to collect host information, including: host name, domain name where the host is located, system architecture, operating system version, and currently logged in user.

[0032] S203, domain information collection: deploy a domain information collection script on the host where the current session is located, use the LDAP protocol to query the AD (Active Directory) directory, and collect basic domain information, including: forest root domain name, all domain controller names, all child domain names, parent domain name, current domain name and primary domain controller name, as well as other domain information such as domain services, logged-in domain users, domain high-authority group members, domain delegation information, etc.

[0033] After the host information is initially collected, the parameters of the information collection script can be dynamically adjusted (for example, increasing the domain controller scanning depth for Windows Server hosts), and key data (such as domain trust relationships) can be filtered in real time to prepare for cross-domain attacks or preload corresponding modules.

[0034] Specifically, first, the host can be classified and judged based on the collected information to form a policy label: if the host runs a server version operating system, it is marked as a "key node" to further identify whether it is a domain controller; if it is a client operating system, such as Windows 10, it is marked as a "normal domain member"; if the system role contains features such as "domain controller", "DNS server", and "file sharing", it is marked as a "high-value target"; if it is not joined to a domain or has no domain information, it is marked as a "non-domain member" or "peripheral host". Then, according to the host classification results, the parameters of information collection are dynamically adjusted. For example, for ordinary domain member hosts: perform basic user information enumeration, obtain login users, domain user group members, service information, scan local open ports and simple LDAP information; for domain controller hosts: increase LDAP deep query, obtain all domain users, domain control lists, domain trust relationships, try to read key account permissions (such as krbtgt), enable ACL enumeration and SID history field recognition, and check whether DCSync attacks or forged tickets are allowed; for high-privileged user active hosts: strengthen the extraction of information such as credentials, tokens, and keys, and activate the in-memory ticket extraction and session monitoring strategy.

[0035] Through these dynamic parameter adjustments, the characteristics of the target host can be accurately matched, redundant scanning can be reduced, and the efficiency of information acquisition and security concealment can be improved. After receiving the scan results, real-time structured analysis is performed, and the following key data items are focused on: domain controller name and IP address, trust relationship between the current domain and other domains (such as parent-child domains, forest trust, external trust), key domain users (such as Enterprise Admins, Domain Admins), domain authority delegation information, service delegation accounts, implicit authority chains, suspicious cross-domain login traces or account usage records, etc. Once these key fields are identified, the subsequent attack value they may bring is immediately evaluated.

[0036] Step 3: Privilege Escalation After the information is collected, the next step is to escalate privileges. If the privileges of the current penetration session are not sufficient for deeper penetration, privilege escalation is required to increase the privilege level of the current session. By escalating privileges, the attacker can gain higher system access rights and perform more attack operations.

[0037] The specific steps of privilege escalation include: S301, permission detection: Check the permissions of the current session to determine whether it is an administrator or system permission (System permission). If the current session permission is low (such as ordinary user permission), it is necessary to enhance the permission. For example, by executing the whoami command to check the current user identity, if the result is DOMAIN\user, it means that the current permission is low; if it is SYSTEM or Administrator, it means that the current permission is high.

[0038] S302. Use known vulnerabilities to escalate privileges: Elevate the privileges of the current session by exploiting operating system vulnerabilities or configuration flaws. For example, use the getsystem command in the MSF (Metasploit) framework or Windows privilege escalation vulnerabilities (such as MS14-058) to escalate privileges.

[0039] S303. If the privilege escalation fails, the reasons for the failure are recorded (such as antivirus software interception), high-risk operations are dynamically blocked (such as disabling the MS14-058 vulnerability exploit), and the current host is marked as a "low-privilege temporary storage target". Wait until other modules succeed before scanning again to escalate privileges.

[0040] Step 4: Lateral movement Lateral movement is an important step in penetration testing, the purpose of which is to expand the scope of attack within the target network and obtain more resources or credentials. Through lateral movement, you can use the permissions you have obtained to gradually penetrate more systems and ultimately control high-privileged users in the domain environment.

[0041] like Figure 2 As shown, the specific steps of lateral movement include: S401, check whether there are high-authority credentials or processes in the domain on the local machine, and if so, directly steal the token; S402, traverse the host that has not been attacked, obtain the host information (such as system version and open ports), and call the corresponding common vulnerability to attack; S403, traverse the unattacked domain services, obtain the service information, and call the corresponding service vulnerability to attack; S404: Use domain-related vulnerabilities to attack the domain environment itself and obtain the credentials of the domain controller's krbtgt user.

[0042] If the token theft (S401) is successful, the vulnerability attack process is immediately suspended, and lateral movement using credentials is prioritized; if the vulnerability attack (S402~404) fails continuously, it automatically switches to password blasting (by trying a large number of possible password combinations to guess the login credentials of the target system in order to obtain unauthorized access rights) or phishing module (by forging trusted communications or interfaces to trick users into providing sensitive information, such as usernames, passwords, etc.).

[0043] Step 5: Cross-domain penetration attack Once sufficient privileges are successfully obtained in the target network, especially the credentials of the domain controller or high-privilege user, the penetration tester can start cross-domain penetration. After the lateral movement is successful, all the acquired sessions and credentials are traversed to select high-privilege sessions and credentials. Using the acquired high-privilege credentials, the root domain is directly attacked through SID-History to obtain the root domain high-privilege credentials. If the SID-History attack fails, Golden Ticket forgery or DNS hijacking is performed.

[0044] During the cross-domain penetration process, you may encounter obstacles from the defense mechanism. At this time, you can adjust the attack strategy (such as delayed attack) to avoid triggering alarms or being identified by the security defense system. Specifically, the security protection level of the root domain can be evaluated based on the following indicators to generate a defense score or strength level:

[0045] Different attack control strategies are adopted according to different defense strength levels. For example: for low defense strength, the attack is executed immediately without hiding, and SID-History is used directly; for medium defense strength, an attack delay is added, normal traffic disguise is simulated before execution, and the attack payload is delayed (such as triggering after 5 to 10 minutes); for high defense strength, the attack frequency is reduced, the time is staggered (such as low peak time in the early morning), user behavior is disguised (simulating normal login), and a more covert alternative is selected (such as forging Golden Ticket or performing DNS hijacking).

[0046] Embodiment 2 Based on the above method, this embodiment provides a multi-module collaborative domain penetration automatic vulnerability exploitation system, such as Figure 3 As shown in the figure, the system mainly includes routing proxy module, information collection module, privilege escalation module, lateral movement module, cross-domain attack module and session management module, and introduces an intelligent orchestration engine to break through the problems of fixed process and single path of traditional penetration testing, and realize dynamic adjustment and optimization of the penetration process.

[0047] in: The routing proxy module is responsible for setting routes for cross-segment attack sessions and adding intranet proxies. Through this module, attackers can establish a reliable communication channel between the border host and the intranet. During the session communication process, the intelligent orchestration engine dynamically allocates routing weights based on the multi-NIC information of the border host (such as giving priority to the network segment with less proxy traffic), and monitors the proxy stability in real time. If the proxy is interrupted, it will automatically rebuild or switch to an alternate route.

[0048] The information collection module is responsible for collecting information about the host where the session is located and obtaining relevant information about the target domain. It collects the operating system information, open ports, domain services and user information of the target host by running specific scripts and scanning tools (such as Nmap and PowerView) to prepare for subsequent penetration behavior. During the information scanning and collection process, the intelligent orchestration engine automatically adjusts the scanning strategy based on the collected information (such as operating system type, open ports, and domain controller information). For example, for Windows domain controllers, the intelligent orchestration engine automatically adjusts script parameters, increases scanning depth and priority, and ensures that the most relevant data is collected.

[0049] The privilege escalation module is responsible for elevating newly launched sessions to high privileges. This module escalates privileges on the target host through automated privilege escalation vulnerability exploits (such as MS14-058, UAC bypass, etc.). If privilege escalation fails, the intelligent orchestration engine will record the reasons for the privilege escalation failure (such as antivirus software interception), dynamically block high-risk operations (such as disabling MS14-058 vulnerability exploits), and mark the current host as a "low-privilege temporary target" and scan back for privilege escalation after other modules succeed.

[0050] The lateral movement module is used to exploit known vulnerabilities or credentials to move laterally in the target network to attack more hosts, especially to obtain high-privileged user credentials in the domain. The focus of the lateral movement module is to obtain new sessions through vulnerability exploitation or credential theft. The cross-domain attack module is responsible for launching cross-domain penetration attacks, especially when obtaining high-privilege credentials, breaking through the security lines between domains and entering the root domain controller by using these credentials. During the cross-domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the cross-domain attack defense strategy. If the target root domain has strong defense, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering alarms and being detected by the defense system.

[0051] The session management module is responsible for tracking and managing all penetration test sessions, recording session information and credentials obtained after a successful cross-domain attack. It continuously monitors the status of the controlled host and promptly updates the session management strategy after a cross-domain attack to ensure the validity of high-privilege sessions and credentials throughout the penetration process.

[0052] Through the collaborative work of the above functional modules, penetration testing can go from breaking through the network boundary to controlling the entire domain network, and the process is more efficient and automated. Each module is responsible for a specific function, but in the actual penetration test process, their collaborative work is crucial. For example, the routing proxy module provides support for cross-segment attacks, the information collection module collects all target data, the privilege escalation module escalates privileges, the lateral movement module expands the attack range, the cross-domain attack module breaks through the domain defense line, and the session management module ensures data tracking and control of the entire attack process. Finally, the penetration path is optimized through the intelligent orchestration engine to improve the test efficiency and success rate.

[0053] The above-mentioned system can execute the multi-module collaborative domain penetration automatic vulnerability exploitation method described in Example 1, and has the corresponding functional modules and beneficial effects of the method. For technical details not described in detail in this embodiment, please refer to the multi-module collaborative domain penetration automatic vulnerability exploitation method provided in Example 1 of the present invention.

[0054] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution, in essence or in other words, the part that contributes to the relevant technology, can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiment.

[0055] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them. Under the concept of the present invention, the technical features in the above embodiments or different embodiments may also be combined, the steps may be implemented in any order, and there are many other changes in different aspects of the present invention as described above, which are not provided in detail for the sake of simplicity. Although the present invention has been described in detail with reference to the aforementioned embodiments, a person of ordinary skill in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A multi-module collaborative domain penetration automatic vulnerability exploitation method, characterized in that: Includes steps: S1. Establish an initial session from the boundary host of the target network, perform cross-segment detection and set up a routing proxy; S2, identify live hosts and open ports in the target network, and collect host information and domain information; S3, elevating the privilege level of the current session through operating system vulnerabilities or configuration flaws; S4. Use the obtained permissions to move laterally and expand the scope of penetration attacks; S5. Carry out cross-domain penetration attack after successful lateral movement.

2. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S1 includes: Obtain and analyze network card information in the initial session to determine whether the host has multiple network segments; if there are multiple network segments, it is necessary to establish routes and set up intranet proxies; monitor proxy stability in real time, and automatically rebuild or switch routes if the proxy is interrupted: assign a dynamic routing weight score to each network segment. If the proxy is interrupted, first try to restart the proxy service on the original path. If the reconstruction fails, enter the backup path switching process and use the backup path with the highest dynamic routing weight score.

3. The domain penetration automatic vulnerability exploitation method according to claim 2, characterized in that: The dynamic routing weight score is expressed as: , in, Indicates i The comprehensive routing weight score of each network segment, Indicates i The available bandwidth ratio of each network segment, and , For the i The current network load of each network segment, The maximum bandwidth of the network card; Indicates i The bandwidth utilization of each network segment, and ; Indicates i The stability coefficient of each network segment, that is, the proxy success rate within the set time; For the i The average response delay ratio of the network segments, w 1~ w 4 is the coefficient of each factor.

4. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S2 includes: Deploy a host information collection script on the host where the current session is located to collect host information, including the host name, domain name where the host is located, system architecture, operating system version, and current logged-in user; Deploy a domain information collection script on the host where the current session is located to collect basic domain information and other domain information. The basic domain information includes the forest root domain name, all domain controller names, all child domain names, the parent domain name, the current domain name and the primary domain controller name. The other domain information includes domain services, logged-in domain users, domain high-authority group members, and domain delegation information.

5. The domain penetration automatic vulnerability exploitation method according to claim 4, characterized in that: After collecting host information, dynamically adjust the parameters of the information collection script and filter key data in real time: First, the host is classified and judged based on the collected information to form a policy label: if the host runs a server version operating system, it is marked as a "key node"; if it is a client operating system, it is marked as a "normal domain member"; if the system role includes "domain controller", "DNS server" and "file sharing", it is marked as a "high-value target"; if it is not joined to the domain or has no domain information, it is marked as a "non-domain member" or "peripheral host"; Then, according to the classification results, the parameters of the information collection script are dynamically adjusted: for "ordinary domain member" hosts, basic user information enumeration is performed to obtain logged-in users, domain user group members, service information, and scan local open ports and simple LDAP information; for "high-value target" hosts, LDAP deep query is added to obtain all domain users, domain control lists, domain trust relationships, try to read key account permissions, enable ACL enumeration and SID history field recognition, and check whether DCSync attacks or forged tickets are allowed; for "key node" hosts, credential, token, and key extraction behaviors are strengthened.

6. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S4 includes: S401, check whether there are high-authority credentials or processes in the domain on the local machine, and if so, directly steal the token; S402, traverse the host that has not been attacked, obtain the host information and call the corresponding common vulnerability to attack; S403, traverse the unattacked domain services, obtain the service information and call the corresponding service vulnerability to attack; S404, using domain-related vulnerabilities to attack the domain environment itself and obtain the credentials of the domain controller's krbtgt user; If the token theft in S401 is successful, the vulnerability attack process will be immediately suspended, and lateral movement using credentials will be prioritized; if the vulnerability attacks in S402~404 fail continuously, it will automatically switch to the password blasting or phishing module.

7. The domain penetration automatic vulnerability exploitation method according to claim 1, characterized in that: Step S5 includes: traversing all acquired sessions and credentials, selecting high-authority sessions and credentials, using the acquired high-authority credentials to directly attack the root domain through SID-History to obtain the root domain high-authority credentials; if the SID-History attack fails, Golden Ticket forgery or DNS hijacking is performed.

8. The domain penetration automatic vulnerability exploitation method according to claim 7, characterized in that: Evaluate the security protection level of the root domain to obtain the defense strength level, and adopt corresponding cross-domain penetration attack strategies according to the defense strength level of the root domain: for low defense strength, execute the attack immediately without hiding, and directly use SID-History; For medium defense intensity, attack strategies include adding attack delays, simulating normal traffic disguise before execution, and delaying the delivery of attack payloads; for high defense intensity, attack strategies include reducing attack frequency, disguising user behavior, Golden Ticket forgery, and DNS hijacking.

9. A domain penetration automatic vulnerability exploitation system based on the method according to any one of claims 1 to 8, characterized in that: It includes routing proxy module, information collection module, privilege escalation module, lateral movement module, cross-domain attack module and intelligent orchestration engine; The routing proxy module is used to set routes for cross-segment attack sessions and add intranet proxies. During session communication, the intelligent orchestration engine dynamically allocates routing weights based on the multi-NIC information of the border host and monitors the proxy stability in real time. If the proxy is interrupted, it automatically rebuilds or switches to an alternate route. The information collection module is used to collect information about the host where the session is located and obtain relevant information about the target domain. The privilege escalation module is used to elevate the privilege level of the session through operating system vulnerabilities or configuration defects. If the privilege escalation fails, the intelligent orchestration engine records the reason for the privilege escalation failure, dynamically blocks high-risk operations, and marks the current host as a "low-privilege temporary storage target"; The lateral movement module is used to utilize known vulnerabilities or credentials to move laterally in the target network and obtain high-privilege user credentials in the domain to expand the scope of penetration attack; The cross-domain attack module is used to launch a cross-domain penetration attack. During the cross-domain penetration process, the intelligent orchestration engine adjusts the attack rhythm according to the cross-domain attack defense strategy. If the target root domain defense is strong, the orchestration engine will automatically delay the attack or switch to other attack methods to avoid triggering an alarm and being detected by the defense system.

10. The domain penetration automatic vulnerability exploitation system according to claim 9, characterized in that: It also includes a session management module, which is responsible for tracking and managing all penetration test sessions, recording session information and credentials obtained after a successful cross-domain attack, continuously monitoring the status of the controlled host, and promptly updating the session management policy after the cross-domain attack to ensure the validity of high-privilege sessions and credentials throughout the entire penetration process.

Citation Information

Patent Citations

  • Network domain security detection method and device based on domain environment

    CN116208368A

  • Transverse penetration attack data processing method, system and device and storage medium

    CN116595513A

  • Network security test and evaluation system and method

    CN118764266A

  • Taking privilege escalation into account in penetration testing campaigns

    US10462177B1